CVE-2012-0644
published 2012-03-08CVE-2012-0644: Race condition in the Passcode Lock feature in Apple iOS before 5.1 allows physically proximate attackers to bypass intended passcode requirements via a…
PriorityP420medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.28%
20.1th percentile
Race condition in the Passcode Lock feature in Apple iOS before 5.1 allows physically proximate attackers to bypass intended passcode requirements via a slide-to-dial gesture.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | < 5.1 | 5.1 |
| puppet | puppet | >= 2.7.0 < 2.7.18 | 2.7.18 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h6fq-pxcw-673j: Race condition in the Passcode Lock feature in Apple iOS before 5
ghsa_unreviewed·2022-05-14
CVE-2012-0644 [MEDIUM] CWE-362 GHSA-h6fq-pxcw-673j: Race condition in the Passcode Lock feature in Apple iOS before 5
Race condition in the Passcode Lock feature in Apple iOS before 5.1 allows physically proximate attackers to bypass intended passcode requirements via a slide-to-dial gesture.
GHSA
Puppet allows local users to obtain sensitive configuration information
ghsa·2017-10-24
CVE-2012-3866 [LOW] Puppet allows local users to obtain sensitive configuration information
Puppet allows local users to obtain sensitive configuration information
`lib/puppet/defaults.rb` in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for `last_run_report.yaml`, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master server to read this file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2679 rhncfg: Insecure permissions used for /var/log/rhncfg-actions file
bugzilla·2012-05-25·CVSS 2.1
CVE-2012-2679 [LOW] CVE-2012-2679 rhncfg: Insecure permissions used for /var/log/rhncfg-actions file
CVE-2012-2679 rhncfg: Insecure permissions used for /var/log/rhncfg-actions file
It was discovered that Red Hat Network Configuration Client set insecure (0644) permissions on the /var/log/rhncfg-actions file used to store (besides terminal) the output of different RHN Client actions (diff, verify etc.). A local attacker could use this flaw to obtain sensitive information, if the rhncfg-client diff action has been used to query differences between the (normally for unprivileged user not readable) config files stored by RHN and those, deployed on the system.
Discussion:
The CVE identifier of CVE-2012-2679 has been assigned for this issue.
---
This issue affects the versions of the rhncfg package, as shipped with Fedora release of 15, 16, and 17. Please schedule an update.
---
Created
Bugzilla
CVE-2012-2389 hostapd: insecure default permissions on /etc/hostapd/hostapd.conf
bugzilla·2012-05-23·CVSS 2.1
CVE-2012-2389 [LOW] CVE-2012-2389 hostapd: insecure default permissions on /etc/hostapd/hostapd.conf
CVE-2012-2389 hostapd: insecure default permissions on /etc/hostapd/hostapd.conf
It was reported [1] that the default permissions of /etc/hostapd/hostapd.conf were insecure (0644) considering they could contain credentials (PSKs, shared radius secrets, etc.) that would then be world readable.
This is a low-impact flaw that be mitigated by changing the permissions to the file (upstream has done this now).
This was assigned CVE-2012-2389 [2] (although no credentials are written by any tools or by default to this file, so an administrator should logically tighten up the permissions if saving sensitive information to the file).
[1] https://bugzilla.novell.com/show_bug.cgi?id=740964
[2] http://www.openwall.com/lists/oss-security/2012/05/23/13
Discussion:
Created hostapd tracking bugs for
2012-03-08
Published